fix(safeio): retain attribute inspection on private create

This commit is contained in:
2026-08-18 13:26:34 +02:00
parent 93f9939be5
commit 835b298212
@@ -461,6 +461,11 @@ func createWindowsPrivateRegularAtWithAccess(parent windows.Handle, name string,
return nil, ErrUnsafeFile
}
defer security.Close()
// The caller's data authority is intentionally preserved (GENERIC_WRITE is used for
// streaming creates), but privateWindowsRegularInfo must inspect attributes and links
// before returning the handle. FILE_READ_ATTRIBUTES grants that inspection without
// adding read-data authority to a write-only create.
access |= windows.FILE_READ_ATTRIBUTES
handle, err := openWindowsRelativeObject(
parent,
name,